SPLK-5001 · Question #53
When should adaptive response actions be used in threat hunting?
The correct answer is D. Adaptive response actions should be used to automate responses to security incidents. Adaptive response actions are designed to automate responses to security incidents, enabling threat hunting platforms (like SIEM/SOAR tools) to trigger predefined actions - such as isolating a host, blocking an IP, or revoking credentials - when specific threat conditions are…
Question
When should adaptive response actions be used in threat hunting?
Options
- AAdaptive response actions should always be used for any security incident.
- BAdaptive response actions are optional and not necessary for threat hunting.
- CAdaptive response actions should only be used for low-risk threats.
- DAdaptive response actions should be used to automate responses to security incidents.
How the community answered
(34 responses)- A3% (1)
- B3% (1)
- C6% (2)
- D88% (30)
Explanation
Adaptive response actions are designed to automate responses to security incidents, enabling threat hunting platforms (like SIEM/SOAR tools) to trigger predefined actions - such as isolating a host, blocking an IP, or revoking credentials - when specific threat conditions are detected, reducing manual effort and response time. Option A is wrong because indiscriminate use for any incident would create noise and operational overhead, making responses unsustainable. Option B is wrong because automation is a core value-add of modern threat hunting frameworks, not an afterthought. Option C is wrong because limiting automated responses to low-risk threats inverts the logic - high-risk threats are precisely where fast, automated containment matters most.
Memory tip: Think of adaptive response as "threat hunting on autopilot" - it adapts to what it finds by automatically responding, not just alerting.
Topics
Community Discussion
No community discussion yet for this question.